Legal

Privacy Policy

How Aladdin AI collects, uses, and protects your data.

Last updated: April 15, 2026

Our Commitment

Aladdin AI ("Aladdin," "we," "us," or "our") operates the website at aladdin-ai.net, the Aladdin web application, and the Aladdin Chrome Extension (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and what rights you have. We are committed to protecting your privacy and handling your data with transparency.

1. Information We Collect

Account & Profile Information

  • Name, email address, and profile photo (via Google OAuth sign-in or email registration)
  • Work experience, education history, skills, and certifications
  • Resume and cover letter content you upload or that we generate for you
  • Job preferences, target roles, and location preferences

Job Data

  • Job postings you analyze or interact with through the Service
  • Job match scores, skill gap analyses, and application status
  • Employer information extracted from job listings

Generated Documents

  • Tailored resumes and cover letters generated by our AI
  • Document quality scores and improvement suggestions

Usage & Analytics Data

  • Pages visited, features used, and actions taken within the Service
  • Device type, browser type, operating system, and screen resolution
  • IP address, approximate geographic location (country/region level)
  • Referral source and session duration

Payment Information

  • Billing details are processed by Stripe. We do not store your full credit card number, CVC, or bank account details on our servers. We receive only a tokenized reference, card brand, last four digits, and expiration date from Stripe.

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service — match you with relevant job postings, generate tailored resumes and cover letters, and track your applications
  • Improve job matching — train and refine our machine learning models using anonymized and aggregated data to improve match accuracy for all users
  • Communicate with you — send transactional emails, document-ready notifications, and product updates (you can opt out of non-essential communications)
  • Ensure security — detect fraud, prevent abuse, and enforce our Terms of Service
  • Analytics — understand usage patterns to improve features, fix bugs, and guide product decisions

We do not sell your personal information to third parties. We do not use your individual resume content to train AI models — only anonymized, aggregated patterns (e.g., which skills appear most frequently in successful applications) are used for model improvement.

3. Chrome Extension Data Collection

The Aladdin Chrome Extension operates with scoped permissions and collects data only in the context of job-seeking activity:

  • Job page analysis — when you visit a job listing on a supported job site (e.g., LinkedIn, Indeed, Greenhouse, Lever), the extension reads the page content to extract job title, company name, requirements, and description for analysis
  • Active tab only — the extension only reads page content on job-related sites when you explicitly trigger an analysis or when our job detection heuristic identifies a job listing. It does not read content on non-job-related websites
  • No browsing history — we do not track, store, or transmit your general browsing history. The extension does not monitor pages outside of recognized job platforms
  • Local processing — initial job detection heuristics run locally in the browser. Only confirmed job listing data is transmitted to our servers for analysis
  • Credential handling — during active automation sessions (when you use the autonomous application agent), the extension may transmit credentials over a secure WebSocket connection (WSS) to fill application forms on your behalf. Credentials are processed ephemerally and are not stored on our servers

4. Gmail Data & Limited Use Disclosure

If you choose to connect your Gmail account, the Service accesses your Gmail data through the Google Gmail API. This section describes exactly what data is accessed, how it is used, and the restrictions we follow.

What Gmail Data We Access

  • Read access (gmail.readonly) — we search your inbox for specific application-related emails only: one-time passwords (OTPs) and verification codes from job application platforms, and application confirmation/status update emails from employers. We do not read, scan, or index your general email content.
  • Send access (gmail.send) — if you use the networking outreach feature, we send emails on your behalf to professional contacts you specify. Every email is initiated by your explicit action and you review the content before sending.

How Gmail Data Is Used

  • OTP codes are extracted and used to complete application forms during automation sessions, then immediately discarded
  • Application status emails are parsed to update your application tracking dashboard
  • Outreach emails are composed based on templates you customize and sent via your Gmail account

How Gmail Tokens Are Stored

  • Gmail OAuth access tokens and refresh tokens are encrypted using AES-256-GCM before storage
  • Encryption keys are managed separately from the database
  • Tokens are only decrypted server-side at the moment of API access
  • You can revoke Gmail access at any time from your account settings, which immediately deletes all stored tokens

Google API Services Limited Use Disclosure

Aladdin AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Gmail data to provide and improve the user-facing features described above (OTP retrieval, application tracking, and outreach sending). No other use is made of this data.
  • We do not use Gmail data for advertising, and we do not serve ads based on Gmail content or metadata.
  • We do not transfer Gmail data to third parties except as necessary to provide the Service (e.g., encrypted transmission to our server for OTP extraction), with your explicit consent, or as required by law. We never sell Gmail data.
  • We do not use Gmail data to train machine learning or AI models. Gmail content is processed ephemerally for the specific features above and is not retained for model training, analytics, or any other purpose.
  • Human access to Gmail data is restricted. No Aladdin AI employee or contractor reads your Gmail content, except (a) with your explicit consent for support purposes, (b) as necessary for security incident investigation, or (c) as required by law.

Gmail data retention: OTP codes are discarded immediately after use. Application status data extracted from emails is stored as part of your application tracking history and is deleted when you delete the corresponding application or your account. Outreach email metadata (recipient, subject, timestamp) is retained for your outreach history; the full email body is not stored on our servers after sending.

5. Third-Party Services

We integrate with the following third-party services, each governed by their own privacy policies:

Google OAuth

Used for authentication. We receive your name, email, and profile photo. We do not access your Google contacts, Drive, or other Google services beyond what is described in the Gmail Data section above.

Google Gmail API

Used for OTP retrieval, application status tracking, and outreach email sending, as described in Section 4. Subject to the Google API Services User Data Policy and Limited Use requirements.

Stripe

Used for payment processing. All payment data is handled by Stripe in compliance with PCI DSS. We never see or store your full card number.

Google Gemini AI

Used for job match scoring, skill gap analysis, and document generation. Job and profile data sent to the Gemini API is processed under Google's data processing terms and is not used by Google to train its models.

Datadog

Used for application performance monitoring and analytics. Datadog collects anonymized usage data (page views, session replays with masked user input, performance metrics) only when you have consented to analytics cookies. No personally identifiable information is sent to Datadog.

6. Data Storage & Security

  • All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • User data is stored in a PostgreSQL database hosted on AWS (US-East-2, Ohio) with automated backups and point-in-time recovery
  • Frequently accessed data (e.g., session tokens, quota counters) is cached in Redis with password authentication and in-memory encryption
  • Gmail OAuth tokens are encrypted with AES-256-GCM using a dedicated encryption key before database storage
  • Authentication uses httpOnly, Secure, SameSite cookies to prevent XSS and CSRF attacks
  • API keys and secrets are stored in environment variables and secret management services, never in source code
  • We conduct regular security audits and employ multiple independent AI code reviewers to catch vulnerabilities before deployment
  • Access to production systems is restricted to authorized personnel with multi-factor authentication

7. Cookies & Tracking

We use the following cookies:

CookiePurposeDurationType
auth_tokenAuthentication session30 daysEssential
access_tokenAPI access55 minutesEssential
aladdin_cookie_consentCookie preference storagePersistentEssential

Analytics cookies are only set when you explicitly consent via our cookie banner. We use Datadog RUM for analytics, which sets session tracking cookies only after consent. Essential cookies cannot be disabled as they are required for the Service to function. We do not use third-party advertising cookies or tracking pixels.

8. Data Retention

Data TypeRetention Period
Account & profile dataUntil you delete your account
Generated documents (resumes, cover letters)Until you delete them, or 90 days after account deletion
Job analysis data12 months from date of analysis
Application tracking dataUntil you delete your account
Gmail OTP codesImmediately discarded after extraction
Gmail OAuth tokensUntil you disconnect Gmail or delete your account
Outreach email metadataUntil you delete your account
Usage analytics (anonymized)24 months
Payment recordsAs required by law (typically 7 years)
Redis cache (sessions, quotas)Ephemeral; expires within hours to days

When you delete your account, we begin purging your personal data within 30 days. Some anonymized, aggregated data (e.g., skill frequency statistics) may be retained indefinitely as it cannot be linked back to you.

9. International Data Transfers

Your data is processed and stored on servers located in the United States (AWS US-East-2, Ohio). If you access the Service from outside the United States, your data will be transferred to and processed in the United States.

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as our legal mechanism for international data transfers. These clauses provide appropriate safeguards for the protection of your personal data when it is transferred outside the EEA.

Our third-party service providers (Stripe, Datadog, Google Cloud) maintain their own data processing agreements and transfer mechanisms. You may request a copy of the applicable Standard Contractual Clauses by contacting us at privacy@aladdin-ai.net.

10. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:

  • Right of access — request a copy of the personal data we hold about you (available via Settings → Data Management → Export Data)
  • Right to rectification — request correction of inaccurate or incomplete personal data (edit directly in your profile)
  • Right to erasure — request deletion of your personal data (available via Settings → Data Management → Delete Account)
  • Right to data portability — receive your personal data in a structured, commonly used, machine-readable format (JSON export)
  • Right to restrict processing — request that we limit how we use your data
  • Right to object — object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent — withdraw consent at any time where processing is based on consent (e.g., analytics cookies can be revoked via the cookie banner)

To exercise any of these rights, use the self-service tools in your account settings or contact us at privacy@aladdin-ai.net. We will respond within 30 days. If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.

Legal basis for processing: (a) performance of a contract (providing the Service), (b) legitimate interest (improving our Service, preventing fraud, and ensuring security), and (c) your consent (where explicitly obtained, such as for analytics cookies and Gmail access).

Data controller: Aladdin AI, contactable at privacy@aladdin-ai.net.

11. Your Rights Under CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights:

  • Right to know — request disclosure of the categories and specific pieces of personal information we have collected about you (available via Settings → Data Management → Export Data)
  • Right to delete — request deletion of your personal information, subject to certain legal exceptions (available via Settings → Data Management → Delete Account)
  • Right to correct — request correction of inaccurate personal information (edit directly in your profile)
  • Right to opt-out of sale/sharing — we do not sell or share your personal information with third parties for cross-context behavioral advertising
  • Right to non-discrimination — we will not discriminate against you for exercising your CCPA/CPRA rights

To submit a verifiable consumer request, use the self-service tools in your account settings or email privacy@aladdin-ai.net. We will verify your identity and respond within 45 days.

12. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal data, we will delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us at privacy@aladdin-ai.net.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by sending you an email notification or displaying a prominent notice within the Service. We encourage you to review this policy periodically to stay informed about how we protect your data.

14. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Aladdin AI

Privacy inquiries: privacy@aladdin-ai.net

Legal inquiries: legal@aladdin-ai.net

Website: aladdin-ai.net